Cybercrime, Formbook campaign via rtf from ChinaThe “AWD-20-971-JA04Q7.doc” attachment of the “Рuгсhasе Огdег #AWD-20-971-JA04Q7” email, exploiting a vulnerability, contacts a link… Cybercrime, Formbook campaign via rtf from China14 March 2023Francesco BussolettiCyber, Defence and Security The “AWD-20-971-JA04Q7.doc” attachment of the “Рuгсhasе Огdег #AWD-20-971-JA04Q7” email, exploiting a vulnerability, contacts a link and downloads an exe: the malware.
Cybercrime, Formbook hidden in a fake purchase order from ZimbabweThe gz attachment of the “ORDER 0736449574 ZWL0106245448” email contains an exe file: the malware. Cybercrime, Formbook hidden in a fake purchase order from Zimbabwe13 February 2023Francesco BussolettiCyber, Defence and Security The gz attachment of the “ORDER 0736449574 ZWL0106245448” email contains an exe file: the malware.
Cybercrime, false DHL invoice baits for a Formbook campaignThe gz attachment of the email with the subject "COMMERCIAL INVOICE, BILL OF LADING, ETC… Cybercrime, false DHL invoice baits for a Formbook campaign9 February 2023Francesco BussolettiDefence and Security, Restricted Area The gz attachment of the email with the subject "COMMERCIAL INVOICE, BILL OF LADING, ETC DOC" contains an exe file: the malware.
Cybercrime, Formbook passes from the UAE and a purchase orderThe gz attachment of the email contains an exe file: the malware. Cybercrime, Formbook passes from the UAE and a purchase order7 February 2023Francesco BussolettiCyber, Defence and Security The gz attachment of the email contains an exe file: the malware.
Cybercrime, RFQ from Thailand via China carries FormbookThe email gz attachment contains an exe file: the malware. Cybercrime, RFQ from Thailand via China carries Formbook6 February 2023Francesco BussolettiDefence and Security, Restricted Area The email gz attachment contains an exe file: the malware.
Cybercrime, double failed malware campaign via POThe emails contain an xls which, using the Equation Editor, contacts a url and downloads… Cybercrime, double failed malware campaign via PO17 January 2023Francesco BussolettiCyber, Defence and Security The emails contain an xls which, using the Equation Editor, contacts a url and downloads the final payload. However, the exe is unreachable.
Cybercrime, double Formbook campaign via SWIFT transaction from Ziraat BankTwo emails have the same .7z attachment that contains an exe file: the malware. Cybercrime, double Formbook campaign via SWIFT transaction from Ziraat Bank23 December 2022Francesco BussolettiCyber, Defence and Security Two emails have the same .7z attachment that contains an exe file: the malware.
Cybercrime, complex Formbook campaign via Libyan oil companiesThe email contains 5 attachments: 4 images and a pdf. By activating the latter, you… Cybercrime, complex Formbook campaign via Libyan oil companies13 December 2022Francesco BussolettiDefence and Security, Restricted Area The email contains 5 attachments: 4 images and a pdf. By activating the latter, you are asked to open a link that downloads an exe: the malware.
Cybercrime, Formbook conveyed via false hotel bookingThe email rar attachment contains an exe file: the malware. Cybercrime, Formbook conveyed via false hotel booking12 December 2022Francesco BussolettiDefence and Security, Restricted Area The email rar attachment contains an exe file: the malware.
Cybercrime, multi-malware campaign via fake purchase orderThe xls attachment of the email first downloaded Putty and now Formbook. It is not… Cybercrime, multi-malware campaign via fake purchase order9 December 2022Francesco BussolettiDefence and Security, Restricted Area The xls attachment of the email first downloaded Putty and now Formbook. It is not excluded that it is targeted.